Commission a Penetration Test: What Does the Kickoff Look Like?

If you're considering commissioning a penetration test, you’re likely grappling with a mix of questions. How transparent is the pricing? What’s the difference between scan-only assessments and manual pentesting? Who will be on the testing team, and how do you communicate with them effectively? Organizations like Hackeroo, binsec group GmbH, and Pentest Collective GmbH offer various services that can help you navigate this complex process.

In this blog post, we'll walk you through what a typical kickoff session looks like when you approve a quote and start testing. Along the way, we’ll highlight key concepts like greybox testing, OSCP-certified testers, and the importance of clear communication to maximize the value of your engagement.

1. Approve Quote and Transparent Pricing

Before any technical work begins, the first step is approving a clear, detailed quote that reflects your testing scope.

It's common to encounter vague pricing models or checklist-only quotes that leave you guessing about what exactly you're paying for. Leading penetration testing firms like binsec group GmbH and Pentest Collective GmbH emphasize transparency. For example, you might expect a daily rate starting at around 1,160€ per day, which is aligned with market averages for manual testing by experienced professionals.

Here’s a simplified example to illustrate how transparent pricing usually looks:

Item Description Price per Day Estimated Days Total Price Manual pentesting Greybox web application assessment with OSCP-certified tester and junior analyst 1,160€ 5 5,800€ Scan-only assessment Automated scans with vulnerability validation 650€ 3 1,950€

When you approve the quote, make sure you understand the scope clearly and confirm what deliverables to expect. This approval is your green light for the testers to prepare and then start on the engagement.

2. Manual Pentesting vs Scan-only Assessments

A critical distinction to appreciate is the difference between manual penetration testing and scan-only assessments.

Scan-only Assessments

Scan-only assessments rely on automated tools that crawl your infrastructure or applications to detect vulnerabilities. While these tools are efficient and can surface common misconfigurations or known CVEs, they tend to generate a high number of false positives and often lack context.

Some providers may market scan-based services as “penetration tests,” but this is a red flag if the deliverable is mainly a tool report dump without expert analysis.

Manual Pentesting

You ever wonder why manual penetration testing involves human experts actively investigating your systems, exploiting vulnerabilities, and assessing the real-world impact of weaknesses. This approach is labor-intensive but provides much more accurate and actionable results.

Companies like Hackeroo differentiate themselves by combining automated scanning with manual validation by OSCP-certified testers, increasing the depth and reliability of findings.

3. OSCP-Certified Testers and Team Composition

When the engagement kicks off, you’ll meet the team assigned to your project. At leading pentest providers, teams are composed of a blend of senior and junior testers to balance experience and coverage.

image

One hallmark of expertise is the OSCP (Offensive Security Certified Professional) certification—recognized globally as a solid indicator that the tester possesses strong manual exploitation skills and deep understanding of penetration testing methodologies.

    Senior testers, often OSCP certified or holding higher qualifications, provide leadership and handle the most complex challenges. Junior testers assist in data collection, follow tactical testing procedures, and help document findings.

This mix helps optimize costs while ensuring quality, as senior testers guide the effort and juniors provide capacity to cover testing scope effectively.

4. Greybox as the Practical Default Testing Approach

Before testing starts, the team will clarify what kind of access and information you will provide. The main options are:

    Blackbox: No prior knowledge or credentials, simulating an external attacker with zero trust. Whitebox: Full access to source code, architecture diagrams, credentials, and more, simulating a worst-case insider threat or very deep analysis. Greybox: Partial knowledge and limited credentials provided to testers.

Greybox testing is internal network pentest the most practical default—it balances realism and efficiency. Testers get enough insight to target high-risk areas but still mimic an attacker without insider privileges.

Both binsec group GmbH and Pentest Collective GmbH advocate for greybox approaches in their standard offerings since it maximizes impact within typical engagement budgets and timelines.

5. The Kickoff Meeting: Setting Expectations and Establishing Communication

The kickoff meeting is the first direct interaction between your team and the penetration testers after the contract is signed and quote approved. Its purpose is to set clear expectations and lay the foundation for smooth communication throughout the engagement.

Typical Kickoff Meeting Agenda

Introductions: The client’s stakeholders and the pentest team members meet. Scope Review: Confirm assets, applications, APIs, and network segments included in the test. Testing Methodology: Discuss manual vs automated elements, greybox access, and test scenarios. Communication Plan: Agree on communication channels (email, Slack, ticketing system), frequency of updates, and escalation procedures. Scheduling and Deliverables: Review timelines for testing phases and final report submission. Rules of Engagement: Outline any off-limits systems, hours of permitted testing, and data handling policies.

For example, Hackeroo schedules a detailed kickoff where clients can ask technical questions directly to OSCP-certified testers. This avoids frustrating sales calls that dodge specifics and helps ensure everyone is aligned on objectives.

image

Communication with Testers During Your Engagement

Good communication is the unsung hero of successful penetration tests. You should expect your pentest provider to offer clear channels for ongoing dialogue, promptly answer technical queries, and provide interim updates if significant findings emerge early.

Make sure that:

    You can approve quote changes swiftly if scope adjustments are needed during testing. You have a direct, technical contact who understands your environment and can explain test progress without jargon. Feedback mechanisms are in place to clarify findings before they go into the final report.

As a client, don’t hesitate to ask your provider upfront how communication will be handled. The best teams embrace transparency and treat you as an active partner rather than a passive recipient.

Summary

Commissioning a penetration test can feel daunting without a clear roadmap. But by focusing on key aspects during the kickoff—transparent pricing, manual testing by OSCP-certified professionals, greybox scope, and effective communication—you set yourself up for a valuable engagement.

Remember, companies like Hackeroo, binsec group GmbH, and Pentest Collective GmbH prioritize these elements to ensure you don't get stuck with confusing reports, vague sales pitches, or scan-only “pentests.” With a proper kickoff and collaborative mindset, you’ll be confident that your approved quote leads to actionable insights and stronger security postures.

Ready to commission your next penetration test? Make sure your kickoff is thorough — it’s the foundation for success.